Proceedings of the ACM on Programming Languages· 2026Q1
ReFun: Reconstructing Function Boundaries in EVM Bytecode
- 1citations
- Q1SCImago
- 2026year
Short summary
ReFun, a novel tool, reconstructs function boundaries in Ethereum Virtual Machine (EVM) bytecode with 94.3% precision and 95.5% recall, resolving ambiguity between function calls and intra-procedural jumps using progressive refinement and probabilistic inference.
AI-generated from the title and abstract; the full text is not read.
Key points
- ReFun reconstructs function boundaries in EVM bytecode by distinguishing function calls from intra-procedural control transfers.
- The approach uses progressive refinement: over-approximating potential calls, rule-based reasoning, and probabilistic inference.
- ReFun achieves 94.3% precision and 95.5% recall on 8,696 real-world Solidity contracts.
- The tool is efficient, identifying functions in 82% of contracts within eight seconds.
- ReFun's output aids downstream tasks like contract decompilation and clone detection.
AI-generated from the title and abstract; the full text is not read.
Abstract
Recovering the structure of a Solidity smart contract from its deployed bytecode is a prerequisite for various downstream analyses, such as control-flow graph construction, decompilation, and clone detection. A central step in this task is identifying private functions. However, since all source-level function boundaries are completely lost after compilation, the major challenge of this task lies in how to differentiate function calls from intra-procedural control transfers, because both are implemented via the JUMP/JUMPI instructions. We observe that although jump-based control transfers are superficially uniform, their context information is different. Some contexts provide definitive evidence of an intra-procedural control transfer or a function call, which inspires us to address this problem through progressive refinement rather than naive binary classification. Specifically, we first construct an over-approximated set of potential function call sites based on EVM execution semantics, and then narrow them down using rule-based reasoning. The remaining uncertain cases are finally resolved through probabilistic inference over suggestive contexts. For each identified function, we further analyze the instructions before each jump to determine its target and reassemble scattered code fragments into a continuous instruction sequence. We implement our approach as an open-source tool, dubbed ReFun, and evaluate it on 8,696 real-world Solidity smart contracts across multiple Solidity compiler versions and optimization settings. The experimental results demonstrate that ReFun achieves 94.3% precision and 95.5% recall in function recovery, and it is also efficient, completing function identification and separation for 82% of contracts within eight seconds per contract. Finally, we show how ReFun is applied to the downstream tasks, including contract decompilation and clone detection.
The authors' abstract, as published at the source. Proceedings of the ACM on Programming Languages, 2026 · DOI ↗
Continue with a free account
Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.
Continue free on the webSign in with Google or Apple; no card needed. You come back to this paper.
On your phone:
Field: Information Systems
Information SystemsComputer Science